CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12392
5.3 MEDIUM

The Cryptocurrency Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_optin_optout' …

Nov 18, 2025
CVE-2025-12391
5.3 MEDIUM

The Restrictions for BuddyPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout() function in …

Nov 18, 2025
CVE-2025-12088
6.4 MEDIUM

The Meta Display Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Meta Display Block in all versions up to, and including, …

Nov 18, 2025
CVE-2025-12079
6.1 MEDIUM

The WP Twitter Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all versions up to, and including, 1.7.4 due …

Nov 18, 2025
CVE-2025-11734
5.4 MEDIUM

The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to unauthorized post modification due to missing …

Nov 18, 2025
CVE-2025-9625
4.3 MEDIUM

The Coil Web Monetization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to …

Nov 18, 2025
CVE-2025-8609
6.4 MEDIUM

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion Block's attributes in all versions up to, …

Nov 18, 2025
CVE-2025-8605
6.4 MEDIUM

The Gutenify – Visual Site Builder Blocks & Site Templates. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in …

Nov 18, 2025
CVE-2025-40545
4.8 MEDIUM

SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect …

Nov 18, 2025
CVE-2025-26391
5.4 MEDIUM

SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a …

Nov 18, 2025
CVE-2025-12962
6.4 MEDIUM

The Local Syndication plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5a via the `url` parameter in …

Nov 18, 2025
CVE-2025-12961
4.3 MEDIUM

The Download Panel plugin for WordPress is vulnerable to unauthorized settings modification due to a missing capability check on the 'wp_ajax_save_settings' AJAX action in all …

Nov 18, 2025
CVE-2025-12937
6.5 MEDIUM

The ACF Flexible Layouts Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'acf_flm_update_template_with_pasted_layout' function …

Nov 18, 2025
CVE-2025-12827
4.3 MEDIUM

The Top Friends plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3. This is due to missing …

Nov 18, 2025
CVE-2025-12823
6.4 MEDIUM

The CSV to SortTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csv' shortcode in all versions up to, and including, 4.2 …

Nov 18, 2025
CVE-2025-12406
6.1 MEDIUM

The Project Honey Pot Spam Trap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is …

Nov 18, 2025
CVE-2025-12404
6.1 MEDIUM

The Like-it plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to missing or …

Nov 18, 2025
CVE-2025-12372
4.3 MEDIUM

The Permalinks Cascade plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.2. This is due to the plugin …

Nov 18, 2025
CVE-2025-12173
4.3 MEDIUM

The WP Admin Microblog plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.1. This is due to …

Nov 18, 2025
CVE-2025-12078
6.1 MEDIUM

The ArtiBot Free Chat Bot for WebSites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all versions up to, and including, …

Nov 18, 2025
CVE-2025-11868
6.4 MEDIUM

The everviz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `everviz` shortcode attributes in versions up to, and including, 1.1. This is …

Nov 18, 2025
CVE-2025-8404
5.5 MEDIUM

Stack buffer overflow vulnerability exists in the Supermicro BMC Shared library. An authenticated attacker with access to the BMC exploit stack buffer via a crafted …

Nov 18, 2025
CVE-2025-11267
6.4 MEDIUM

The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_veu_custom_css' parameter in all versions up to, …

Nov 18, 2025
CVE-2025-11265
6.4 MEDIUM

The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_cta_url' and 'vkExUnit_cta_button_text' parameters in all versions …

Nov 18, 2025
CVE-2025-7623
5.4 MEDIUM

Stack-based buffer overflow in the SMASH-CLP shell. An authenticated attacker with SSH access to the BMC can exploit a stack buffer overflow via a crafted …

Nov 18, 2025
CVE-2025-12524
5.4 MEDIUM

The Post Type Switcher plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.0.0 due to missing validation …

Nov 18, 2025
CVE-2025-52578
5.7 MEDIUM

Incorrect Usage of Seeds in Pseudo-Random Number Generator (CWE- 335) vulnerability in the High Sec ELM may allow a sophisticated attacker with physical access, to …

Nov 18, 2025
CVE-2025-52457
5.7 MEDIUM

Observable Timing Discrepancy (CWE-208) in HBUS devices may allow an attacker with physical access to the device to extract device-specific keys, potentially compromising further site …

Nov 18, 2025
CVE-2025-6599
5.3 MEDIUM

An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an attacker to perform Slowloris‑style denial‑of‑service …

Nov 18, 2025
CVE-2025-13325
6.3 MEDIUM

A vulnerability was determined in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /enrollment_edit1.php. Executing manipulation of the …

Nov 18, 2025
CVE-2025-13306
6.3 MEDIUM

A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation …

Nov 18, 2025
CVE-2025-7711
5.4 MEDIUM

The The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, …

Nov 17, 2025
CVE-2025-64766
5.3 MEDIUM

NixOS's Onlyoffice is a software suite that offers online and offline tools for document editing, collaboration, and management. In versions from 22.11 to before 25.05 …

Nov 17, 2025
CVE-2025-13303
6.3 MEDIUM

A vulnerability was determined in code-projects Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /search-edit.php. This manipulation of …

Nov 17, 2025
CVE-2025-13302
4.7 MEDIUM

A vulnerability was identified in code-projects Courier Management System 1.0. This affects an unknown part of the file /add-new-officer.php. Such manipulation of the argument ManagerName …

Nov 17, 2025
CVE-2025-36299
4.3 MEDIUM

IBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could be used in further attacks against the system.

Nov 17, 2025
CVE-2024-44664
6.5 MEDIUM

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php.

Nov 17, 2025
CVE-2024-44661
5.4 MEDIUM

PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php.

Nov 17, 2025
CVE-2024-46335
4.6 MEDIUM

PHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parameters in between-date-userreport.php.

Nov 17, 2025
CVE-2024-44663
6.5 MEDIUM

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php.

Nov 17, 2025
CVE-2024-44662
6.5 MEDIUM

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page.

Nov 17, 2025
CVE-2024-44660
6.5 MEDIUM

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php.

Nov 17, 2025
CVE-2024-44658
6.5 MEDIUM

PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the subcategory and category parameters in subcategory.php.

Nov 17, 2025
CVE-2024-44655
6.1 MEDIUM

PHPGurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) via the search parameter in user-search.php.

Nov 17, 2025
CVE-2024-44654
6.5 MEDIUM

PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the email and mobileno parameters in reset-password.php.

Nov 17, 2025
CVE-2025-64758
4.8 MEDIUM

@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organizations to identify and reduce risk in …

Nov 17, 2025
CVE-2025-55059
4.8 MEDIUM

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Nov 17, 2025
CVE-2025-55058
4.5 MEDIUM

CWE-20 Improper Input Validation

Nov 17, 2025
CVE-2025-55057
4.5 MEDIUM

Multiple CWE-352 Cross-Site Request Forgery (CSRF)

Nov 17, 2025
CVE-2025-55056
4.8 MEDIUM

Multiple CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Nov 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.